GPU VulnDB

Database/Control plane, storage & DevOps

Nagios Log Server: group-writable sudo scripts let the web user replace a root script and get root

CVSS 8.5CVE-2025-34323Control plane, storage & DevOpscurated

Impact

The www-data user that runs the Log Server web application is in the nagios group, which has write access to /usr/local/nagioslogserver/scripts, while several root-owned scripts in that directory are runnable through sudo with no password. Anyone executing as www-data can move a root-owned script aside, drop a replacement at the same path, and invoke it under sudo for arbitrary root command execution - full compromise of the appliance OS. For an operator that means any web-tier bug in the log server, or any shell as the web user, becomes root on the box that holds the fleet's aggregated logs: audit trail tampering, credentials for the systems it polls, and a trusted pivot into the management network.

Who can reach it

Local code execution as www-data on the Log Server host - typically chained from a web-application flaw or from any existing low-privileged shell. No password or sudo credential is needed; the sudo rules are passwordless. Not exploitable by an unauthenticated remote attacker on its own.

What to do

Upgrade to Nagios Log Server 2026R1.0.1 or later, which is the vendor fix, and restart the appliance services; the upgrade is an in-place package update rather than a reboot. If an upgrade cannot be scheduled immediately, remove the nagios group's write permission on /usr/local/nagioslogserver/scripts and narrow the passwordless sudo rules that point into that directory.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.